Update the CSI Secret Identity to use a BYO Managed User and Setup the required federation
khowling opened this issue · 4 comments
khowling commented
Gordonby commented
It is specific to the workload (service account) - so perhaps more relevant to https://github.com/Azure-Samples/java-aks-keyvault-tls ?
khowling commented
Good Shout, but we've been having issues consuming aksc in a workload repo, selecting csi&keyvault options, then configuring the workload to use it with federated identity. I cant see how its possible at the moment without the workload repo needing to create their own keyvault. This pattern need attention!
Gordonby commented
Agreed, I think the app would need their own keyvault. Rbac will become tricky.
github-actions commented
Issue smells stale, no activity for 30 days. Stale Label will be removed if the issue is updated, otherwise closed in a month.